Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
warringaa
New Contributor

Default allow ICMP

Is there a way to default allow icmp messages through the whole fortigate firewall? It' s a bit annoying to create default icmp policy rules between every vlan.
2 REPLIES 2
ede_pfau
SuperUser
SuperUser

Hi, and welcome to the forums. ICMP is in no way special compared to other IP traffic. If you want to allow it across interfaces then you have to explicitly allow it in the policy. To make life easier Fortinet gave us the service group object. If you add ICMP or PING to your custom service group that you use in every policy between VLANs then you' re done in a second.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Paul_Dean
Contributor

If your VLANs will be setup in the same way requiring the same policies you could create a Zone. Add all of your interfaces into the Zone and create a policy of Zone to Zone ICMP allow. Intra-zone traffic is allowed by default.
NSE4
NSE4
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors